Replies: 1 comment 6 replies
-
|
Traffic should be flowing to the LME server on 9200 and coming back at that higher port number. netsh wfp show filters |
Beta Was this translation helpful? Give feedback.
6 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
I'm still piloting/learning LME. I thought things were working fine with just two pilot Windows servers setup. However, when the Elastic Agent is running, the Event Viewer shows Audit Failures occurring every 1-3 seconds, generating 1000s of audit entries. This message is repeated with only the destination port changing:
The Windows Filtering Platform has blocked a packet.
Application Information:
Process ID: 0
Application Name: -
Network Information:
Direction: Inbound
Source Address: x.x.x.x
Source Port: 9200
Destination Address: z.z.z.z
Destination Port: 53241
Protocol: 6
Filter Information:
Filter Run-Time ID: 148600
Layer Name: Transport
Layer Run-Time ID: 13
The Source Address is the IP of our LME server and the Destination Address is the Windows server. This scenario happens on both servers. Shutting down Elastic Agent makes it stop and a Windows Firewall rule to allow the LME server on port 9200 does nothing to help.
Endless web searching doesn't point me to anything or a solution. Any ideas?
Beta Was this translation helpful? Give feedback.
All reactions